Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-09-06 00:15
Updated : 2026-09-08 20:51
NVD link : CVE-2025-58375
Mitre link : CVE-2025-58375
CVE.ORG link : CVE-2025-58375
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
